NERC CIP — Critical Infrastructure Protection Standards
NERC CIP is a set of mandatory cybersecurity standards for the bulk electric system in North America. Enforced by FERC, the 14 active standards (CIP-002 through CIP-015) cover asset categorisation, electronic security perimeters, personnel training, incident response, and supply chain risk management. Non-compliance carries financial penalties.
14
Active Standards
FERC
Enforced By
CIP-015
Latest (2025)
Mandatory
For BES Operators
BES Cyber System impact rating (High/Medium/Low) and security management controls, policies, and governance.
Security awareness training, background checks, electronic security perimeters, and remote access controls.
Physical security plans for BES Cyber Systems, patch management, malware prevention, and ports/services controls.
Cyber security incident reporting within 1 hour for certain categories, recovery plans with annual testing requirements.
Configuration change management, information protection, supply chain risk management, and internal network security monitoring (CIP-015 effective Oct 2028).
Categorize all assets per CIP-002 impact ratings (High, Medium, Low) based on their role in the bulk electric system.
Define and document Electronic Security Perimeters (ESPs) and Interactive Remote Access controls per CIP-005.
Implement CIP-004 security awareness training, background verification, and access authorization procedures.
Deploy CIP-006 physical protection measures at facilities housing applicable BES Cyber Systems.
Create, document, and annually test incident response (CIP-008) and recovery plans (CIP-009).
Maintain comprehensive evidence documentation for NERC compliance audits and self-certifications.